Re: [stable] Linux 2.6.25.10

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Greg KH <greg@...>
Cc: Tiago Assumpcao <tiago@...>, Andrew Morton <akpm@...>, Linus Torvalds <torvalds@...>, <linux-kernel@...>, <stable@...>
Date: Wednesday, July 16, 2008 - 1:25 pm

On 16 Jul 2008 at 9:29, Greg KH wrote:


what do you not believe in? that a task refcount leak can be exploited
for privilege elevation?


i never post exploits. however spender did write at least a proof-of-concept
that triggers it and proves that it's potentially exploitable. writing a
weaponized version takes a whole lot more effort than it's worth for us
(though i bet others have been working on it ever since if they didn't
already write one when the bug got introduced).


what i said was *not* specific to this bug at all, any local privilege
elevation bug can be used to, well, elevate privileges, regardless of
how one gets into a box. the browser example was just that, to highlight
that even single home user systems may very well be affected. sure, the
browser bug is not your problem, but the local privilege elevation due
to kernel bugs *is*. your wording was wrong, untrusted users are only
*one* potential kind of threat therefore if only such systems update,
many others will remain vulnerable.


why isn't it useful? i've been asking every one of you who said so and
have yet to receive a reasonable justification. remember, your own
employers do it 'all the time', it must be useful to someone.

and what's with this 'all the time'? if you guys fix security bugs all
the time, then yes, you are expected to announce them all the time. if
you think that reflects badly on the quality of the kernel code, then
maybe you should think over your development process that results in
security fixes 'all the time'.


if you are not qualified to do this job then don't do it. noone forced
you to accept this task. look at Chris Wright, he has no problems with
disclosing the security issues and he actually publicly pledged to do
his best to do so (and i hope he won't revert his position now).

cheers,
  PaX Team

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 4:18 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 4:23 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 4:42 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 5:18 pm)
Re: [stable] Linux 2.6.25.10, Rafael C. de Almeida, (Thu Jul 17, 3:19 am)
Re: [stable] Linux 2.6.25.10, , (Thu Jul 17, 3:59 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 5:26 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 6:08 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 7:28 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 8:04 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:24 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 8:56 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:08 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 9:23 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 8:00 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 9:08 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 9:53 pm)
Re: [stable] Linux 2.6.25.10, Casey Schaufler, (Tue Jul 15, 11:27 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:33 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Wed Jul 16, 9:21 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 11:16 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 12:13 am)
Re: [stable] Linux 2.6.25.10, Casey Schaufler, (Wed Jul 16, 1:26 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 12:21 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 1:02 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 1:13 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 10:02 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 10:36 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 12:07 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 12:16 am)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 9:30 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:16 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 8:38 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:51 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 9:10 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 11:13 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:01 am)
Re: [stable] Linux 2.6.25.10, Greg KH, (Wed Jul 16, 10:43 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 11:43 am)
Re: [stable] Linux 2.6.25.10, Greg KH, (Wed Jul 16, 12:29 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 1:25 pm)
Re: [stable] Linux 2.6.25.10, Mike Galbraith, (Wed Jul 16, 11:43 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Wed Jul 16, 2:08 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 3:09 pm)
Re: [stable] Linux 2.6.25.10, Gabor Gombas, (Wed Jul 16, 5:35 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:04 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:41 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:49 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 6:08 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:23 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 6:31 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:51 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 7:04 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 7:52 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 10:24 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 11:11 pm)